* Patches from FreeBSD, Conectiva, Gentoo, others * Beware new Sober variant * Google search cache spawns SSL fear, and other interesting reading
endif; ?>Editor’s note: With the Thanksgiving holiday here, this is our only newsletter this week. For a reminder of things we should be thankful for, read Ellen Messmer’s latest Security Notes entry: http://www.nwfusion.com/weblogs/security/006818.html?nl
Editor’s note: With the Thanksgiving holiday here, this is our only newsletter this week. For a reminder of things we should be thankful for, read Ellen Messmer’s latest Security Notes entry:
https://www.nwfusion.com/weblogs/security/006818.html?nl
Happy Thanksgiving to all of our readers!
Today’s bug patches and security alerts:
Flaws found in Linux SMB file system
A denial-of-service vulnerability has been found in the SMB file system that is part of many Linux operating system kernels. An attacker would need control of the SMB server to carry out the attack or be able to intercept data bound for the affected server. For more, go to:
https://security.e-matters.de/advisories/142004.html
**********
iDefense warns of flaws in Fcron
Four security flaws have been found in Fcron, a scheduling tool that replaces Vixie Cron. The flaws could be exploited to bypass configuration settings, delete files, create files with root permission, and kill processes on the affected machine. For more, go to:
https://www.nwfusion.com/go2/1122bug1a.html
Related Gentoo advisory:
https://security.gentoo.org/glsa/glsa-200411-27.xml
**********
DoS in 3Com OfficeConnect ADSL Wireless 11g Firewall Router
A flaw in the way UDP traffic is handled by the 3Com OfficeConnect ADSL Wireless 11g Firewall Router could be exploited in a denial-of-service attack against the device. For more, go to:
**********
FreeBSD releases patch for Fetch
A buffer overflow in the Fetch file transfer utility could be exploited to overwrite memory and run the attacker’s code of choice. For more, go to:
https://www.nwfusion.com/go2/1122bug1b.html
**********
NGSSoftware warns of WinRAR vulnerability
An undisclosed flaw in WinRAR, a repair and archive tool, has been found by security experts at NGSSoftware. The company is not releasing details for three months. Users can upgrade to version 3.41 to fix the problem:
NGSSoftware advisory:
https://www.nextgenss.com/advisories/winrar.txt
**********
Conectiva patches subversion
All versions of subversion, a file change tracking system, including 1.0.7 are vulnerable to leaking meta data. This information could be used for other malicious purposes. For more, go to:
https://www.nwfusion.com/go2/1122bug1c.html
Conectiva updates libtiff3
Several integer overflow vulnerabilities found in previous versions of libtiff3, an image viewer application, have been patched. For more, go to:
https://www.nwfusion.com/go2/1122bug1d.html
Conectiva releases fix for xpdf
A flaw in various implementations of a PDF viewer application could be exploited to crash the affected application or potentially run arbitrary code on the affected machine. For more, go to:
https://www.nwfusion.com/go2/1122bug1e.html
**********
Gentoo patches Portage, Gentoolkit
Both Portage and Gentoolkit for Gentoo Linux have security issues around the creation of temporary files. These files could make the system vulnerable to a symlink attack. For more, go to:
https://security.gentoo.org/glsa/glsa-200411-13.xml
Gentoo releases updates for OpenSSL, Groff
Similar to the announcement above, OpenSSL and Groff are both vulnerable to symlink attacks because of the way temporary files are created. For more, go to:
https://security.gentoo.org/glsa/glsa-200411-15.xml
Gentoo issues fix for zgv
A buffer overflow has been discovered in zgv, an image viewer application for Gentoo. An attacker could exploit this to run their code of choice on the affected machine. For more, go to:
https://security.gentoo.org/glsa/glsa-200411-12.xml
Updates available from Gentoo for Kaffeine, gxine
Buffer overflow vulnerabilities have been found in Kaffeine and gxine. They could be exploited via content access through a malicious Web server. For more, go to:
https://security.gentoo.org/glsa/glsa-200411-14.xml
**********
eEye reports vulnerability in Kerio Personal Firewall
According to an alert from eEye, “eEye Digital Security has discovered a severe denial-of-service vulnerability in the Kerio Personal Firewall product for Windows. The vulnerability allows a remote attacker to reliably render a system inoperative with one single packet.” For more, go to:
https://www.eeye.com/html/research/advisories/AD20041109.html
Kerio advisory:
https://www.kerio.com/security_advisory.html
**********
Today’s roundup of virus alerts:
New Sober variant spreading
A new version of the Sober e-mail worm started spreading in Europe on Friday, according to anti-virus vendors, which have given the worm a midlevel threat rating. IDG News Service, 11/19/04.
https://www.nwfusion.com/news/2004/1119newsober.html?nl
W32/Rbot-PX – This bot can be used for many malicious purposes after it infects a machine through network shares. It installs “crss.exe” in the Windows System directory and allows backdoor access via IRC. (Sophos)
W32/Rbot-PY – This variant installs “MCAFFEFLD.EXE” in the Windows System folder and can log keystrokes to the file “SYSZZY32.TXT”. (Sophos)
W32/Rbot-QE – An Rbot variant that exploits the Windows LSASS vulnerability as it spreads via network shares. It installs “XPUpdate.exe” in the Windows System directory and can be used to log keystrokes, launch denial-of-service attacks, steal CD keys and download/run code from the Internet. (Sophos)
W32/Agobot-NZ – An Agobot variant that installs “gmsvc32.exe” in the Windows System directory. It modifies the Windows HOSTS file to prevent access to specific anti-virus and security Web sites. (Sophos)
W32/Agobot-OC – This Agobot variant tries to hide itself in the file “halflife2.exe”, taking advantage of Microsoft’s latest game’s popularity. It too modifies the HOSTS file to limit access to security-related Web sites. (Sophos)
W32/Primat-C – A virus that uses peer-to-peer networks to spread, infecting .exe, .scr and .pif files. On the 18th of the month, it displays an image on the infected machine’s screen. (Sophos)
W32/Forbot-CP – A Forbot variant that infects “iexplore.exe” in the Windows System directory and provides backdoor access via IRC. The worm may act as a proxy, steal CD key data and delete network shares. (Sophos)
Skulls – A new virus that infects mobile devices running the Symbian operating system. It is spread through an infected SIS file called “Extended Theme Manager” and offered by a user called “Tee-222”. It will display a bunch of skulls on the infected device’s screen. (F-Secure)
Troj/Narod-D – A backdoor virus that opens port 3128 and listens for commands. It installs the file “systemp.exe” in the Windows System directory along with two DLLs. (Sophos)
W32/Bofra-H – Another Bofra variant that spreads via e-mail. The infected attached file always ends in 32.exe. It allows backdoor access to the infected system via IRC. (Sophos)
**********
From the interesting reading department:
Google search cache spawns SSL fear
It’s proving tougher than anticipated to protect SSL VPNs from the voracious caching machine housed inside Google Desktop Search. Network World, 11/22/04.
https://www.nwfusion.com/news/2004/112204google.html?nl
IP VPNs save, but they can carry ‘gotchas’
While IP VPNs are widely accepted as an effective remote access and WAN technology that can save money, there are hidden challenges users should be aware of to avoid costly problems. Network World, 11/22/04.
https://www.nwfusion.com/news/2004/112204vpnhidden.html?nl
E-comm gains offset by escalating fraud
Just in time for the start of the holiday shopping season, two vendors released research last week detailing a rise in e-commerce fraud. CyberSource published the results of its sixth annual e-commerce fraud survey, while VeriSign came out with its fourth Internet Security Intelligence Briefing, which details Internet usage trends as well as threat, vulnerability and fraud patterns. Network World, 11/22/04.
https://www.nwfusion.com/news/2004/112204ecomm.html?nl
Vendors aim to tamp down spyware
Spyware protection debuts in both desktop and gateway products. Network World, 11/22/04.
https://www.nwfusion.com/news/2004/112204spy.html?nl
Oracle announces quarterly patching schedule
Oracle plans to begin issuing cumulative software patches for Oracle Database, E-Business Suite, Application Server, Oracle Enterprise Manager and Collaboration Suite on a quarterly basis beginning Jan. 18. Network World Fusion, 11/18/04.
https://www.nwfusion.com/news/2004/1118orpatch.html?nl
Sybari offers security for IM, SharePoint
Sybari Software Thursday added Antigen 8.0 for Microsoft SharePoint and Antigen 8.0 for Instant Messaging, two anti-virus, anti-spam, and content-filtering security software products for enterprise environments. InfoWorld, 11/19/04.




